CVE-2023-41715

Severity CVSS v4.0:
Pending analysis
Type:
CWE-269 Improper Privilege Management
Publication date:
17/10/2023
Last modified:
02/05/2025

Description

SonicOS post-authentication Improper Privilege Management vulnerability in the SonicOS SSL VPN Tunnel allows users to elevate their privileges inside the tunnel.<br />

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:sonicwall:sonicos:*:*:*:*:*:*:*:* 7.0.1-5145 (excluding)
cpe:2.3:h:sonicwall:nsa2700:-:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:nsa3700:-:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:nsa4700:-:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:nsa5700:-:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:nsa6700:-:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:nssp10700:-:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:nssp11700:-:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:nssp13700:-:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:nssp15700:-:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:nsv10:-:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:nsv100:-:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:nsv1600:-:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:nsv200:-:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:nsv25:-:*:*:*:*:*:*:*